#!/bin/bash

## Copyright (C) 2026 - 2026 ENCRYPTED SUPPORT LLC <adrelanos@whonix.org>
## See the file COPYING for copying conditions.

## AI-Assisted

## debian:trixie-slim carries only the base system, and ca-certificates is
## Priority: standard, so it is absent. Without a trust store apt cannot talk
## https, which we need for additional safety. We could just install
## ca-certificates directly in the Dockerfile, but this script lets us make
## sure it provides the files we expect too.

set -x
set -o errexit
set -o nounset
set -o pipefail
set -o errtrace
shopt -s inherit_errexit
shopt -s shift_verbose

apt-get update

DEBIAN_FRONTEND=noninteractive \
   apt-get install \
      --no-install-recommends \
      --yes \
      ca-certificates

if [ ! -s /etc/ssl/certs/ca-certificates.crt ]; then
   printf '%s\n' "${BASH_SOURCE[0]}: ERROR: /etc/ssl/certs/ca-certificates.crt missing or empty after install." >&2
   exit 1
fi

apt-get clean
